<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: alert in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/alert/m-p/215696#M41177</link>
    <description>&lt;P&gt;Assuming this is a ClusterXL cluster, members would likely be expired on the passive also since this is all set on the management.&lt;BR /&gt;And what precise accounts are we talking about here? Gaia OS user accounts? VPN User accounts? Admin accounts?&lt;/P&gt;</description>
    <pubDate>Thu, 30 May 2024 13:00:43 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-05-30T13:00:43Z</dc:date>
    <item>
      <title>alert</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/alert/m-p/215394#M41139</link>
      <description>&lt;P&gt;is there a way to notify the Admin about local user expiry using smtp?&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2024 16:12:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/alert/m-p/215394#M41139</guid>
      <dc:creator>tavi0906</dc:creator>
      <dc:date>2024-05-28T16:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: alert</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/alert/m-p/215402#M41140</link>
      <description>&lt;P&gt;admin can get warning when they login. this is configured in Smart Console:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Configuring Default Expiration for&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_adminscap variable"&gt;Administrators&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;If you want to use the same expiration settings for multiple accounts, you can set the default expiration for&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_admin variable"&gt;administrator&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;accounts. You can also choose to show notifications about the approaching expiration date at the time when an&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_admin variable"&gt;administrator&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;logs into&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_con variable"&gt;SmartConsole&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;or one of the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_con variable"&gt;SmartConsole&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;clients. The remaining number of days, during which the account will be alive, shows in the status bar.&lt;/P&gt;
&lt;P class="Procedure_Heading"&gt;To configure the default expiration settings:&lt;/P&gt;
&lt;OL&gt;
&lt;LI value="1"&gt;
&lt;P&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;&lt;SPAN class="mc-variable Vars_Other.tp_set variable"&gt;Manage &amp;amp; Settings&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt; Permissions &amp;amp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_adminscap variable"&gt;Administrators&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt; Advanced&lt;/SPAN&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="2"&gt;
&lt;P&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Advanced&lt;/SPAN&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="3"&gt;
&lt;P&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Default Expiration Date&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;section, select a setting:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Never expires&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Expire at&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Select the expiration date from the calendar control&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Expire after&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Enter the number of days, months, or years (from the day the account is made) before&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_admin variable"&gt;administrator&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;accounts expire&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI value="4"&gt;
&lt;P&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Expiration notifications&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;section, select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Show 'about to expire' indication in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_admins variable"&gt;administrators&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;view&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and select the number of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;days in advance&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to show the message about the approaching expiration date.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="5"&gt;
&lt;P&gt;Publish the SmartConsole session.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have never seen an option to send an e-mail regarding this. E-mails are more for system alerts and or if a firewall rules is being 'hit'.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2024 17:43:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/alert/m-p/215402#M41140</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-05-28T17:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: alert</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/alert/m-p/215595#M41158</link>
      <description>&lt;P&gt;This is an existing setup with an Active (A) / Passive (B) configuration. Since we have no access to the Active Firewall (A) due to all local accounts expiring without notifications, we are planning to initiate a failover via SmartConsole. Is this the best approach instead of disconnecting physical connections?&lt;/P&gt;&lt;P&gt;After failover, we will conduct account recovery (referencing sk163461) for the Active Firewall (A). Alternatively, is there a way to modify the expired local user account from Firewall (B) after the failover?&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 04:00:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/alert/m-p/215595#M41158</guid>
      <dc:creator>tavi0906</dc:creator>
      <dc:date>2024-05-30T04:00:08Z</dc:date>
    </item>
    <item>
      <title>Re: alert</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/alert/m-p/215696#M41177</link>
      <description>&lt;P&gt;Assuming this is a ClusterXL cluster, members would likely be expired on the passive also since this is all set on the management.&lt;BR /&gt;And what precise accounts are we talking about here? Gaia OS user accounts? VPN User accounts? Admin accounts?&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 13:00:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/alert/m-p/215696#M41177</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-05-30T13:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: alert</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/alert/m-p/215700#M41179</link>
      <description>&lt;P&gt;Yes, this is clusterXL . we can able to login to standby firewall. we are talking about admin accounts and GAIA OS user accounts.&lt;/P&gt;&lt;P&gt;how can we recover the all accounts on active one ? and can we change the priority of standby in smart console to become active one ?&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 13:20:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/alert/m-p/215700#M41179</guid>
      <dc:creator>tavi0906</dc:creator>
      <dc:date>2024-05-30T13:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: alert</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/alert/m-p/215709#M41180</link>
      <description>&lt;P&gt;Are these firewalls plus management servers, or just firewalls?&lt;/P&gt;
&lt;P&gt;If they are just firewalls, do you have access to the command line of the management server which manages them?&lt;/P&gt;
&lt;P&gt;If so, you may be able to use this to run commands on the firewall:&lt;/P&gt;
&lt;P&gt;cprid_util -verbose -server "&amp;lt;firewall address&amp;gt;" rexec -rcmd &amp;lt;some command here&amp;gt;&lt;/P&gt;
&lt;P&gt;Replace &amp;lt;firewall address&amp;gt; with the main IP address of the cluster member where you want to run the command. For example, this would add a new administrative user to a firewall (or cluster member) with the main IP 10.20.30.40:&lt;/P&gt;
&lt;P&gt;cprid_util -verbose -server "10.20.30.40" rexec -rcmd clish -s -c "add user someNewUser uid 0 homedir /home/someNewUser"&lt;/P&gt;
&lt;P&gt;If the returned data includes "&lt;SPAN&gt;(NULL BUF)", that means the management couldn't connect to CPRID on the firewall or member.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 14:09:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/alert/m-p/215709#M41180</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2024-05-30T14:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: alert</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/alert/m-p/215749#M41186</link>
      <description>&lt;P&gt;Is there any sk which shows the above procedure. if yes, please share.&lt;/P&gt;&lt;P&gt;And also can we follow this&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk106490" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk106490&lt;/A&gt;&amp;nbsp;&amp;nbsp;to reset the password ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 16:24:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/alert/m-p/215749#M41186</guid>
      <dc:creator>tavi0906</dc:creator>
      <dc:date>2024-05-30T16:24:31Z</dc:date>
    </item>
  </channel>
</rss>

